[PATCH] usb: gadget: lpc32xx_udc: cancel pullup work on remove
From: Hongyan Xu
Date: Mon Sep 28 2026 - 10:02:15 EST
Several device interrupts can queue pullup_job, whose callback accesses
the UDC and its I2C transceiver. The IRQs are device-managed, so they
remain registered throughout the driver remove callback, and no path
drains work queued before the resources are released.
Disable and synchronize all publishing IRQs, then cancel pullup_job
before putting the I2C device and releasing the UDC resources.
Fixes: 24a28e428351 ("USB: gadget driver for LPC32xx")
Signed-off-by: Hongyan Xu <getshell@xxxxxxxxxx>
---
drivers/usb/gadget/udc/lpc32xx_udc.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/drivers/usb/gadget/udc/lpc32xx_udc.c b/drivers/usb/gadget/udc/lpc32xx_udc.c
index 044c31869cfb..0a784c9252c5 100644
--- a/drivers/usb/gadget/udc/lpc32xx_udc.c
+++ b/drivers/usb/gadget/udc/lpc32xx_udc.c
@@ -3184,9 +3184,15 @@ static void lpc32xx_udc_remove(struct platform_device *pdev)
return;
}
+ disable_irq(udc->udp_irq[IRQ_USB_LP]);
+ disable_irq(udc->udp_irq[IRQ_USB_HP]);
+ disable_irq(udc->udp_irq[IRQ_USB_DEVDMA]);
+ disable_irq(udc->udp_irq[IRQ_USB_ATX]);
+
udc_clk_set(udc, 1);
udc_disable(udc);
pullup(udc, 0);
+ cancel_work_sync(&udc->pullup_job);
device_init_wakeup(&pdev->dev, 0);
remove_debug_file(udc);
--
2.50.1.windows.1